Reusable decision kit
Approved-data boundary card
A plain-language rule for what may and may not enter an AI trial.
What the completed kit should do
Participants can make the same information-handling decision without guessing.
Capture these facts in your approved system
- Allowed public, synthetic, de-identified, or specifically approved examples
- Prohibited personal, confidential, regulated, credential, and contract-restricted data
- Approved product, plan, configuration, connectors, and participants
- Retention, training use, review, subprocessor, deletion, and export evidence
- Owner, approval path, incident contact, review date, and closeout
Use the structure in this order
- 01
Classify the workflow information.
- 02
Verify the applicable provider controls and terms.
- 03
Publish a short allowed and prohibited rule.
- 04
Train participants and review exceptions before use.
Close the evidence loop
A participant can decide whether an example is allowed and knows where to ask before proceeding.
Keep sensitive material out of this site
- This template is not a privacy, legal, security, records, or sector conclusion.
- De-identification can fail when context or combinations make a person recognizable.
- Provider features and terms can change. Keep dated evidence.